A network access method and device, and a storage medium

By establishing a VPN tunnel in electronic devices to enable direct communication between electronic devices and target resource devices, the problem of users being unable to access resources inside and outside the campus at the same time is solved, improving user experience and reducing communication latency.

CN116566765BActive Publication Date: 2026-02-03CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310613160.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-26
Publication Date
2026-02-03
Estimated Expiration
2043-05-26

AI Technical Summary

Technical Problem

Users cannot access network resources both on and off campus simultaneously, and existing technologies result in poor user experience and high communication latency.

Method used

By establishing a Virtual Private Network (VPN) tunnel in an electronic device, direct communication between the electronic device and the target resource device is achieved. The target resource device is determined based on the correspondence between the network access address and the resource device, and a network access request is sent through the VPN tunnel.

Benefits of technology

It enables simultaneous access to resources both on and off campus, improving user experience and reducing transmission latency for communication services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566765B_ABST
    Figure CN116566765B_ABST
Patent Text Reader

Abstract

The application provides a network access method and device and a storage medium, relates to the technical field of communication, and aims to solve the technical problem that the existing network access method reduces user experience. The network access method comprises the following steps: receiving a network access request sent by a terminal; the network access request comprises a target network access address; reading the correspondence between the network access address and a resource device, and determining a target resource device corresponding to the target network access address; when the electronic device belongs to a transmission network corresponding to a second network transmission mode, the target network access address is a network access address corresponding to a first network transmission mode, and the first network transmission mode is a private network transmission mode, sending the network access request to the target resource device through a virtual private network (VPN) tunnel; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and in particular to a network access method, device and storage medium. BACKGROUND

[0002] For colleges and universities, most of them have established their own campus networks. The campus network is used to access network resources such as library systems and educational administration systems in colleges and universities. When users access the network through the campus network, they can only access network resources within the campus, and cannot access public network resources. Or, when users access the network through an operator network, they can only access public network resources, and cannot access network resources within the campus.

[0003] Currently, users can access network resources within and outside the campus through a near-end manual switching method, but cannot access network resources within and outside the campus at the same time. Users can also use a far-end routing proxy method to access network resources within and outside the campus at the same time, but the access delay is high, resulting in poor user experience. SUMMARY

[0004] The present application provides a network access method, device and storage medium, which solves the technical problem that the existing network access method in the prior art reduces user experience.

[0005] To achieve the above purpose, the present application adopts the following technical solutions:

[0006] In a first aspect, a network access method is provided, applied to an electronic device; the network access method comprises: receiving a network access request sent by a terminal; the network access request comprises a target network access address; reading a correspondence between network access addresses and resource devices, and determining a target resource device corresponding to the target network access address; the correspondence comprises a correspondence between network access addresses and resource devices in a first network transmission mode and a correspondence between network access addresses and resource devices in a second network transmission mode; when the electronic device belongs to a transmission network corresponding to the second network transmission mode, and the target network access address is a network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode, sending the network access request to the target resource device through a virtual private network (VPN) tunnel; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device.

[0007] Optionally, before receiving the network access request sent by the terminal, the network access method further includes: receiving target domain name information sent by the terminal; reading the correspondence between domain name information and network transmission methods, determining the target network transmission method corresponding to the target domain name information, and sending the target domain name information to the target domain name resolution device corresponding to the target network transmission method; receiving the target network access address sent by the target domain name resolution device; the target network access address is obtained by resolving the target domain name information; and sending the target network access address to the terminal so that the terminal generates a network access request based on the target network access address.

[0008] Optionally, before receiving the target domain name information sent by the terminal, the network access method further includes: receiving an Internet Protocol (IP) address request message sent by the terminal and sending the IP address request message to the portal website (PORTAL WEB) device; the IP address request message is used to request the terminal's private network IP address; receiving a prompt message generated by the PORTAL WEB device based on the IP address request message and sending the prompt message to the terminal; the prompt message is used to prompt the terminal to send authentication information; receiving the authentication information sent by the terminal and sending the authentication information to the PORTAL authentication device; the authentication information is used to instruct the PORTAL authentication device to send authentication information to the remote user dial-up authentication (RADIUS) device and to instruct the RADIUS device to authenticate the authentication information; in response to the received authentication confirmation message indicating successful authentication of the authentication information, determining the terminal's private network IP address and sending the private network IP address to the terminal.

[0009] Optionally, it also includes: receiving a message to be transmitted sent by the terminal; the message to be transmitted includes the terminal's private network IP address; determining the terminal's public network IP address corresponding to the terminal's private network IP address according to the mapping relationship between private network IP addresses and public network IP addresses, and updating the terminal's private network IP address to the terminal's public network IP address; in the mapping relationship between private network IP addresses and public network IP addresses, one public network IP address corresponds to multiple private network IP addresses; sending the updated message to be transmitted; the updated message to be transmitted includes the terminal's public network IP address.

[0010] Secondly, a network access device is provided, applied to an electronic device; comprising: a receiving unit, a reading unit, a processing unit, and a sending unit; the receiving unit is used to receive a network access request sent by a terminal; the network access request includes a target network access address; the reading unit is used to read the correspondence between the network access address and a resource device; the processing unit is used to determine the target resource device corresponding to the target network access address; the correspondence includes the correspondence between the network access address and the resource device in a first network transmission mode and the correspondence between the network access address and the resource device in a second network transmission mode; the sending unit is used to send a network access request to the target resource device through a Virtual Private Network (VPN) tunnel when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device.

[0011] Optionally, the receiving unit is further configured to receive target domain name information sent by the terminal; the reading unit is further configured to read the correspondence between domain name information and network transmission methods; the processing unit is further configured to determine the target network transmission method corresponding to the target domain name information; the sending unit is further configured to send the target domain name information to the target domain name resolution device corresponding to the target network transmission method; the receiving unit is further configured to receive the target network access address sent by the target domain name resolution device; the target network access address is obtained by resolving the target domain name information; the sending unit is further configured to send the target network access address to the terminal, so that the terminal generates a network access request based on the target network access address.

[0012] Optionally, the receiving unit is further configured to receive an Internet Protocol (IP) address request message sent by the terminal; the sending unit is further configured to send an IP address request message to the portal web device; the IP address request message is used to request the terminal's private network IP address; the receiving unit is further configured to receive a prompt message generated by the portal web device based on the IP address request message; the sending unit is further configured to send a prompt message to the terminal; the prompt message is used to prompt the terminal to send authentication information; the receiving unit is further configured to receive authentication information sent by the terminal; the sending unit is further configured to send authentication information to the portal authentication device; the authentication information is used to instruct the portal authentication device to send authentication information to the remote user dial-up authentication RADIUS device, and to instruct the RADIUS device to authenticate the authentication information; the processing unit is further configured to determine the terminal's private network IP address in response to a received authentication confirmation message indicating successful authentication of the authentication information; the sending unit is further configured to send the private network IP address to the terminal.

[0013] Optionally, the receiving unit is further configured to receive a message to be transmitted sent by the terminal; the message to be transmitted includes the terminal's private network IP address; the processing unit is further configured to determine the terminal's public network IP address corresponding to the terminal's private network IP address according to the correspondence between private network IP addresses and public network IP addresses; the processing unit is further configured to update the terminal's private network IP address to the terminal's public network IP address; in the correspondence between private network IP addresses and public network IP addresses, one public network IP address corresponds to multiple private network IP addresses; the sending unit is further configured to send the updated message to be transmitted; the updated message to be transmitted includes the terminal's public network IP address.

[0014] Thirdly, a network access device is provided, including a memory and a processor; the memory is used to store computer-executed instructions, and the processor is connected to the memory via a bus; when the network access device is running, the processor executes the computer-executed instructions stored in the memory to cause the network access device to perform the network access method of the first aspect.

[0015] The network access device may be a network device or a component of a network device, such as a chip system within the network device. The chip system supports the network device in implementing the functions involved in the first aspect and any of its possible implementations, such as acquiring, determining, and transmitting data and / or information involved in the aforementioned network access method. The chip system includes a chip, but may also include other discrete devices or circuit structures.

[0016] Fourthly, a computer-readable storage medium is provided, comprising computer-executable instructions that, when executed on a computer, cause the computer to perform the network access method of the first aspect.

[0017] Fifthly, a computer program product is also provided, which includes computer instructions that, when executed on a network access device, cause the network access device to perform the network access method as described in the first aspect.

[0018] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on a computer-readable storage medium. This computer-readable storage medium may be packaged together with the processor of the network access device, or it may be packaged separately from the processor of the network access device; this application does not limit this.

[0019] The descriptions of the second, third, fourth, and fifth aspects of this application can be referenced to the detailed description of the first aspect.

[0020] In the embodiments of this application, the names of the aforementioned network access devices do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. For example, the receiving unit may also be called a receiving module, receiver, etc. As long as the functions of each device or functional module are similar to those of this application, they fall within the scope of the claims of this application and their equivalents.

[0021] The technical solution provided in this application brings at least the following beneficial effects:

[0022] Based on any of the above aspects, this application provides a network access method applied to an electronic device. The network access method includes: the electronic device receiving a network access request sent by a terminal. The network access request includes a target network access address. Then, the electronic device can read the correspondence between the network access address and a resource device, and determine the target resource device corresponding to the target network access address. The correspondence includes the correspondence between the network access address and the resource device in a first network transmission mode and the correspondence between the network access address and the resource device in a second network transmission mode. Subsequently, when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode, the electronic device can send a network access request to the target resource device through a Virtual Private Network (VPN) tunnel. The VPN tunnel is a direct communication tunnel between the electronic device and the target resource device.

[0023] As shown above, electronic devices can determine the target resource device corresponding to the target network access address based on the mapping between network access addresses and resource devices, and send a network access request according to the network transmission method corresponding to the target resource device. Since the mapping includes the mapping between network access addresses and resource devices in the first network transmission method and the mapping between network access addresses and resource devices in the second network transmission method, electronic devices can simultaneously access the resource device corresponding to either the first network transmission method or the resource device corresponding to the second network transmission method, without needing to manually switch between them, thus improving the user experience.

[0024] Furthermore, since the VPN tunnel is a direct communication tunnel between electronic devices and target resource devices, electronic devices belonging to the second network transmission mode can transmit data to the resource devices corresponding to the first network transmission mode faster through the direct communication tunnel, without having to go through multiple nodes of the backbone network and the education network, thus reducing the transmission latency of communication services.

[0025] The beneficial effects of the first, second, third, fourth, and fifth aspects of this application can all be referred to in the analysis of the above-mentioned beneficial effects, and will not be repeated here. Attached Figure Description

[0026] Figure 1 This is a schematic diagram of a near-end manual switching method provided in an embodiment of this application;

[0027] Figure 2 This is a schematic diagram of a remote routing proxy method provided in an embodiment of this application;

[0028] Figure 3 A schematic diagram of a long Internet path provided for an embodiment of this application;

[0029] Figure 4 A schematic diagram of the structure of a network access system provided in this application embodiment. Figure 1 ;

[0030] Figure 5 A schematic diagram of the structure of a network access system provided in this application embodiment. Figure 2 ;

[0031] Figure 6 A schematic diagram illustrating a terminal accessing a resource device corresponding to a public network via a broadband network, provided in an embodiment of this application;

[0032] Figure 7 A schematic diagram illustrating a terminal accessing a campus network resource device via a broadband network, provided in an embodiment of this application;

[0033] Figure 8 A schematic diagram of the hardware structure of a network access device provided in this application embodiment. Figure 1 ;

[0034] Figure 9 A schematic diagram of the hardware structure of a network access device provided in this application embodiment. Figure 2 ;

[0035] Figure 10 A flowchart illustrating a network access method provided in this application embodiment. Figure 1 ;

[0036] Figure 11 This application provides a schematic diagram illustrating a process for a terminal to access a resource device via a broadband network, as illustrated in an embodiment of the present application.

[0037] Figure 12 A schematic diagram of a direct communication tunnel provided for an embodiment of this application;

[0038] Figure 13 A flowchart illustrating a network access method provided in this application embodiment. Figure 2 ;

[0039] Figure 14This application provides a schematic diagram illustrating a process for a terminal to access a domain name resolution device via a broadband network.

[0040] Figure 15 A flowchart illustrating a network access method provided in this application embodiment. Figure 3 ;

[0041] Figure 16 A schematic diagram illustrating a process for a terminal to obtain an IP address, provided as an embodiment of this application;

[0042] Figure 17 A flowchart illustrating a network access method provided in this application embodiment. Figure 4 ;

[0043] Figure 18 A comparative diagram of CGN and NAT provided for an embodiment of this application;

[0044] Figure 19 A flowchart illustrating a network access method provided in this application embodiment. Figure 5 ;

[0045] Figure 20 This application provides an illustration of the effect of using the network access method provided in this application embodiment. Figure 1 ;

[0046] Figure 21 This application provides an illustration of the effect of using the network access method provided in this application embodiment. Figure 2 ;

[0047] Figure 22 This is a schematic diagram of the structure of a network access device provided in an embodiment of this application. Detailed Implementation

[0048] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0049] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0050] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0051] Currently, users can access network resources on and off campus via their terminals (i.e., the terminals they own) through either manual switching at the local end or remote routing proxy.

[0052] Figure 1 A schematic diagram of a method for network access via manual switching at the near end is shown. Figure 1 As shown, terminal 101 can access resource devices outside the campus through the operator's broadband network. The network access request initiated by terminal 101 can pass through a Passive Optical Network (PON) node 102, such as an Optical Line Terminal (OLT) or Optical Network Unit (ONU). Then it passes through a large Layer 2 switch 103, followed by a BAS 104, and finally accesses the resource devices outside the campus through the backbone network. Similarly, terminal 111 (e.g., a Personal Computer (PC) or Wireless Access Point (AP)) can initiate a network access request through the campus network provided by the university to access resource devices within the campus. The network access request sent by terminal 111 can pass through switch 110, BAS 109, firewall device 107, and then reach the resource device 108 within the campus, enabling terminal 111 to access the resource device 108 within the campus.

[0053] The near-end manual switching method refers to the process where, after terminal 101 accesses the network via the operator's broadband network, it can access network resources outside the campus through that network. Simultaneously, the user can open the installed Virtual Private Network (VPN) software on terminal 101. In response to this, terminal 101 establishes a VPN tunnel to network resources within the campus. With the VPN software running, terminal 101 can access these campus resources through the VPN tunnel. This is achieved by adding a VPN tunnel to the Layer 4 network model, enabling terminal 101 to access campus network resources via the VPN tunnel.

[0054] However, when a user wants to access network resources outside the campus, the user needs to disable the VPN software on terminal 101. Therefore, terminal 101 can access network resources within the campus by responding to the user's action of opening the VPN software, and access network resources outside the campus by responding to the user's action of disabling the VPN software. It cannot access both network resources within and outside the campus simultaneously, resulting in a poor user experience.

[0055] Figure 2 This diagram illustrates the structure of a method for network access via a remote routing proxy. Figure 2 As shown, the remote routing proxy method refers to the following: when the terminal accesses a carrier's broadband network, terminal 201 can respond to the user's action of opening VPN software, opening the installed VPN software, and establishing a VPN tunnel with the campus network resources. Subsequently, when terminal 201 accesses campus network resources, it can send a network access request to the campus egress router 206. Later, when the egress router 206 determines that the network access request is for accessing campus network resources, it sends the network access resource to the corresponding campus resource device 208, enabling the terminal to access the campus network resources.

[0056] Alternatively, when the egress router 206 determines that the network access request is for accessing network resources outside the campus, the egress router 206 sends a network access request to the corresponding resource device outside the campus, enabling the terminal 201 to access the network resources outside the campus. In this case, the terminal 201 can access both network resources within the campus and network resources outside the campus without needing to close the VPN software in response to the user's shutdown operation.

[0057] However, because VPN tunnels are built on long-haul internet paths, which include the backbone network and the education and research network (ERN), network access requests must pass through multiple nodes on the backbone network and the ERN network when passing through the VPN tunnel, resulting in high transmission latency for communication services.

[0058] For example, Figure 3 A schematic diagram of a long path on the Internet is shown. (For example...) Figure 3 As shown, after terminal 301 initiates a network access request, it needs to traverse a long path through the internet, including the operator's broadband network, the operator's backbone network outside the province, the operator's national backbone network and the National Education and Research Network (CERNET), and finally the provincial education network, before reaching the campus intranet. Therefore, the network access request initiated by terminal 301 needs to pass through multiple nodes, resulting in high transmission latency for communication services.

[0059] To address the aforementioned problems, this application provides a network access method applied to an electronic device. The network access method includes: the electronic device receiving a network access request sent by a terminal. The network access request includes a target network access address. Subsequently, the electronic device reads the mapping relationship between the network access address and resource devices, and determines the target resource device corresponding to the target network access address. The mapping relationship includes the mapping relationship between the network access address and resource devices in a first network transmission mode and the mapping relationship between the network access address and resource devices in a second network transmission mode. Later, when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode, the electronic device can send a network access request to the target resource device through a Virtual Private Network (VPN) tunnel. The VPN tunnel is a direct communication tunnel between the electronic device and the target resource device.

[0060] As shown above, electronic devices can determine the target resource device corresponding to the target network access address based on the mapping between network access addresses and resource devices, and send a network access request according to the network transmission method corresponding to the target resource device. Since the mapping includes the mapping between network access addresses and resource devices in the first network transmission method and the mapping between network access addresses and resource devices in the second network transmission method, electronic devices can simultaneously access the resource device corresponding to either the first network transmission method or the resource device corresponding to the second network transmission method, without needing to manually switch between them, thus improving the user experience.

[0061] Furthermore, since the VPN tunnel is a direct communication tunnel between electronic devices and target resource devices, electronic devices belonging to the second network transmission mode can transmit data to the resource devices corresponding to the first network transmission mode faster through the direct communication tunnel, without having to go through multiple nodes of the backbone network and the education network, thus reducing the transmission latency of communication services.

[0062] This network access method is applicable to network access systems. Figure 4 One structure of this network access system is shown. For example... Figure 4 As shown, the network access system includes: electronic device 401, multiple resource devices 402, and terminal 403.

[0063] Among them, electronic device 401 is communicatively connected to multiple resource devices 402 and terminals 403.

[0064] It should be noted that when the transmission network to which electronic device 401 belongs is different from the transmission network to which a certain resource device 102 belongs (for example, the transmission network to which electronic device 401 belongs is a public network, while the transmission network to which a certain resource device 102 belongs is a campus private network), electronic device 401 and resource device 402 communicate and connect through a VPN tunnel.

[0065] In this application, electronic device 401 is used to receive network access requests sent by terminal 403 and forward the network access requests sent by the terminal to multiple resource devices 402. Correspondingly, after receiving a network access request, resource device 402 is used to send the network resources corresponding to the network access request to electronic device 401. Then, electronic device 401 forwards the network resources corresponding to the network access request to terminal 403.

[0066] Optionally, electronic device 401 may be a broadband access server (BAS), an interconnection gateway device, or an electronic device that integrates the BAS and the interconnection gateway device. This application embodiment does not limit this.

[0067] Optionally, the physical devices of the multiple resource devices 402 may be servers that provide network resources to the terminals.

[0068] The aforementioned terminal may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connectivity, or other processing device connected to a wireless modem. The terminal may communicate with one or more core networks via a radio access network (RAN). The terminal may be a mobile terminal, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal, or a portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile device that exchanges voice and / or data with the radio access network, such as a mobile phone, tablet computer, laptop computer, netbook, or personal digital assistant (PDA).

[0069] Optionally, the server mentioned above can be one of the servers in a server cluster (composed of multiple servers), a chip in the server, a system-on-a-chip in the server, or a virtual machine (VM) deployed on a physical machine. This application embodiment does not limit this.

[0070] In one feasible approach, when the BAS and the interconnect gateway device are not integrated together... Figure 5 This illustrates another architecture for the network access system. (Combined) Figure 4 ,likeFigure 5 As shown, the network access system includes: terminal 501, ONU 502, OLT 503, switch 504, BAS 505, OLT 506, interconnection gateway device 507, domain name resolution device 508, PORTALWEB device 509, PORTAL authentication device 510, Radius device 511, switch 512, BAS 513, firewall device 514, campus resource device 515, and domain name resolution device 516.

[0071] Specifically, terminal 501, ONU 502, OLT 503, switch 504, and BAS 505 are connected in sequence for communication. Switch 504 is connected to OLT 506 for communication. OLT 506 is connected to the interconnection gateway device 507 for communication. BAS 505 is connected to the domain name resolution device 508, PORTAL WEB device 509, PORTAL authentication device 510, and Radius device 511 for communication. The interconnection gateway device is connected to switch 512 through a VPN tunnel. Switch 512, BAS 513, firewall device 514, and campus resource device 515 are connected in sequence for communication. BAS 513 is connected to the domain name resolution device 516 for communication.

[0072] In this application, terminal 501 initiates a network access request. The network access request passes sequentially through ONU 502, OLT 503, switch 504, and finally reaches BAS 505. When BAS 505 determines that the network access request is for accessing data from a resource device outside the campus, BAS 505 sends the network access request to the resource device corresponding to the network access request. When BAS 505 determines that the network access request is for accessing data from a resource device within the campus, BAS 505 sends the network access request to switch 504. Subsequently, the network access request passes sequentially through OLT 506, interconnection gateway device 507, switch 512, BAS 513, firewall device 514, and finally reaches the resource device 515 within the campus.

[0073] Terminal 501 is also used to send domain name information. The domain name information passes sequentially through ONU 502, OLT 503, switch 504, and BAS 505. Then, BAS 505 sends the domain name information to switch 504, and then the domain name information passes sequentially through OLT 506 and interconnection gateway device 507. When interconnection gateway device 507 determines that the domain name information is from outside the campus, interconnection gateway device 507 sends the domain name information to OLT 506. After that, the domain name information passes sequentially through OLT 506, switch 504, and BAS 505, and finally reaches domain name resolution device 508.

[0074] Terminal 501 is also used to send Internet Protocol (IP) address request messages. The IP address request messages pass through ONU502, OLT503, switch 504, and BAS505 in sequence. Then BAS505 assigns an IP address to terminal 501 through PORTAL WEB device 509, PORTAL authentication device 510, and Radius device 511.

[0075] Optionally, the VPN tunnel can also communicate directly with the BAS513 or firewall device 514.

[0076] For example, suppose the transmission network to which the terminal belongs is a broadband network provided by an operator (also known as a public network). Figure 6 This diagram illustrates a terminal accessing a public network resource device via a broadband network. Figure 6 As shown, when a terminal accesses a public network resource device via a broadband network provided by an operator, and the electronic device is a BAS (Broadband Access System), after the terminal 601 initiates a network access request, the request needs to pass through the ONU 602 and OLT 603 in the metropolitan area network access layer, then reach the aggregation switch 604 in the metropolitan area network aggregation layer, and finally reach the BAS 605 in the metropolitan area network aggregation layer. Next, the BAS 605 sends a network access request to the core router (CR) 606 in the metropolitan area network core layer. Subsequently, the network access request reaches the target resource device accessed by the terminal 601.

[0077] Figure 7 This diagram illustrates a terminal accessing campus network resources via a broadband network. Figure 7 As shown, when a terminal accesses resource devices corresponding to a campus network (also known as a private network or dedicated network) through a broadband network provided by an operator, and the BAS and interconnection gateway devices are not integrated, after the terminal 701 initiates a network access request, the network access request passes through the ONU 702 and OLT 703 of the first metropolitan area network access layer, then reaches the aggregation switch 704 of the metropolitan area network aggregation layer, and then reaches the BAS 705 of the metropolitan area network aggregation layer. Afterwards, the BAS 705 determines that the target resource device corresponding to the network access request initiated by the terminal is a resource device corresponding to the campus network, therefore, the BAS 705 sends a network access request to the aggregation switch 704. Next, the aggregation switch 704 sends a network access request to the interconnection gateway device 710 through the OLT 708 and ONU 709 of the second metropolitan area network access layer. Subsequently, the interconnection gateway device 710 sends a network access request to the resource devices of the campus network corresponding to the network access request (which may include the firewall 711 and the target resource device 712). In this way, the terminal can access the resource devices corresponding to the campus network through the broadband network provided by the operator.

[0078] The basic hardware structure of electronic device 401 includes Figure 8 or Figure 9 The network access device shown includes the following components. Figure 8 and Figure 9 Taking the network access device shown as an example, the hardware structure of electronic device 401 is introduced.

[0079] like Figure 8 The diagram shown is a hardware structure schematic of a network access device provided in an embodiment of this application. The network access device includes a processor 21, a memory 22, a communication interface 23, and a bus 24. The processor 21, memory 22, and communication interface 23 are connected via the bus 24.

[0080] Processor 21 is the control center of the network access device. It can be a single processor or a collective term for multiple processing elements. For example, processor 21 can be a general-purpose central processing unit (CPU) or other general-purpose processors. Among them, the general-purpose processor can be a microprocessor or any conventional processor.

[0081] As one embodiment, processor 21 may include one or more CPUs, for example Figure 6 CPU 0 and CPU 1 are shown in the diagram.

[0082] The memory 22 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0083] In one possible implementation, the memory 22 can exist independently of the processor 21. The memory 22 can be connected to the processor 21 via a bus 24 and is used to store instructions or program code. When the processor 21 calls and executes the instructions or program code stored in the memory 22, it can implement the network access method provided in the following embodiments of this application.

[0084] In this embodiment, the software programs stored in the memory 22 differ for electronic device 101, resulting in different functions implemented by electronic device 401. The functions performed by each device will be described in conjunction with the following flowcharts.

[0085] In another possible implementation, the memory 22 can also be integrated with the processor 21.

[0086] Communication interface 23 is used for the network access device to connect with other devices via a communication network, such as Ethernet, wireless access network, wireless local area network (WLAN), etc. Communication interface 23 may include a receiving unit for receiving data and a sending unit for sending data.

[0087] Bus 24 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0088] Figure 9 Another hardware structure of the network access device in an embodiment of this application is shown. For example... Figure 9 As shown, the network access device may include a processor 31 and a communication interface 32. The processor 31 is coupled to the communication interface 32.

[0089] The functions of processor 31 can be referred to in the description of processor 21 above. In addition, processor 31 also has a storage function, and can perform the functions of memory 22 mentioned above.

[0090] The communication interface 32 is used to provide data to the processor 31. The communication interface 32 can be an internal interface of the network access device or an external interface of the network access device (equivalent to communication interface 23).

[0091] It should be pointed out that, Figure 8 (or Figure 9 The structure shown in the diagram does not constitute a limitation on the network access device, except... Figure 8 (or Figure 9In addition to the components shown in the diagram, the network access device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0092] The network access method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0093] The network access method provided in this application embodiment is applied to Figure 4 Electronic device 401 in the network access system shown, such as Figure 10 As shown, the network access method provided in this application embodiment includes:

[0094] S1001, The electronic device receives a network access request sent by the terminal.

[0095] The network access request includes the target network access address.

[0096] Optionally, the network access address can be the IP address of the resource device to which the requested resource belongs.

[0097] Specifically, when a terminal accesses a target network resource, it can send a target network access request to the target resource device corresponding to the target network resource based on the target resource device's IP address. Since the target resource device and the terminal communicate via an electronic device, the electronic device can receive the network access request sent by the terminal.

[0098] S1002. The electronic device reads the correspondence between the network access address and the resource device, and determines the target resource device corresponding to the target network access address.

[0099] The correspondence includes the correspondence between network access addresses and resource devices in the first network transmission mode and the correspondence between network access addresses and resource devices in the second network transmission mode.

[0100] Specifically, upon receiving a network access request, since the request carries a target network access address, and the electronic device stores the mappings between network access addresses and resource devices for both the first and second network transmission methods, the electronic device can first determine the network transmission method corresponding to the target network access address, then read the mapping between that network transmission method and the resource device to determine the target resource device. In this way, regardless of whether the target network access address is the address of a resource device corresponding to the first or second network transmission method, the electronic device can access the resource device corresponding to the different network transmission methods based on the mapping between the network access address and the resource device.

[0101] Optionally, of the first network transmission method and the second network transmission method, one can be a public network (also known as a public network) transmission method, and the other can be a private network (also known as a private network) transmission method.

[0102] For example, suppose that in the first network transmission method and the second network transmission method, one is a broadband network provided by an operator (i.e., the public network in this application) and the other is a campus network provided by a university (i.e., the private network in this application), and the BAS and the interconnection gateway device are not integrated into a single electronic device. Figure 11 A schematic diagram illustrating a process by which a terminal accesses resource devices via a broadband network is shown. Figure 11 As shown, the process of a terminal accessing resource devices through a broadband network includes:

[0103] S1101, The terminal initiates a network access request through the broadband network.

[0104] Combination Figure 10 The relevant description of the terminal initiating a network access request through the broadband network can be found in the relevant description of S1001, and will not be repeated here.

[0105] S1102, BAS receives network access requests initiated by the terminal.

[0106] Combination Figure 10 The description of the network access request initiated by the BAS receiving terminal can be found in the description of S1001, and will not be repeated here.

[0107] S1103, BAS determines whether the target resource device corresponding to the target network access address in the network access request is a resource device corresponding to the campus network.

[0108] Combination Figure 10 The relevant description of BAS determining whether the target resource device corresponding to the target network access address in the network access request is the resource device corresponding to the campus network can be found in the relevant description of S1002, and will not be repeated here.

[0109] S1104. When the target network access address is not the resource device corresponding to the campus network, the BAS determines that the target resource device is the resource device corresponding to the public network. The BAS sends the network access request to the resource device corresponding to the public network through its own Internet exit.

[0110] Combination Figure 10When the target network access address is not the resource device corresponding to the campus network, the BAS determines that the target resource device is the resource device corresponding to the public network. For details on how the BAS sends the network access request to the resource device corresponding to the public network through its own internet exit, please refer to the relevant description in S1002, which will not be repeated here.

[0111] S1105. When the target network access address is a resource device corresponding to the campus network, BAS sends a network access request to the interconnection gateway device through a VPN tunnel.

[0112] Combination Figure 10 When the target network access address is a resource device corresponding to the campus network, the relevant description of BAS sending a network access request to the interconnection gateway device through the VPN tunnel can be found in the relevant description in S1003, and will not be repeated here.

[0113] S1106. The interconnection gateway device sends a network access request to the target resource device through the routing forwarding table.

[0114] Combination Figure 10 The description of the network access request initiated by the BAS receiving terminal can be found in the relevant description of S1003, and will not be repeated here.

[0115] S1107. When the target resource device sends the target resource to the terminal, the interconnection gateway device sets up a backhaul static route so that the target resource can be sent to the terminal through the BAS.

[0116] Combination Figure 10 When the target resource device sends the target resource to the terminal, the interconnection gateway device sets up a backhaul static route so that the target resource can be sent to the terminal through the BAS. For related descriptions, please refer to the relevant description in S1003, which will not be repeated here.

[0117] In another possible method, one of the first network transmission method and the other of the second network transmission method can be a first dedicated network transmission method and the other can be a second dedicated network transmission method.

[0118] For example, suppose the first private network transmission method is the network transmission method of the first enterprise, and the second private network transmission method is the network transmission method of the second enterprise. Then, the terminal of the first enterprise can access the resource device corresponding to the second private network transmission method through electronic devices, and the terminal can access the resource device of the second enterprise.

[0119] S1003. When the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode, the electronic device sends a network access request to the target resource device through a virtual private network (VPN) tunnel.

[0120] In this context, a VPN tunnel is a direct communication tunnel between an electronic device and a target resource device. The transmission network corresponding to the network transmission mode to which the terminal belongs is the same as the transmission network corresponding to the network transmission mode to which the electronic device belongs.

[0121] Specifically, when the target network access address is the network access address corresponding to the first network transmission method, and the first network transmission method is a private network transmission method, and the electronic device belongs to the transmission network corresponding to the second network transmission method, then the target resource device corresponding to the target network access address belongs to the transmission network corresponding to the first network transmission method. Since resource devices in the private network transmission method do not allow access from devices in other network transmission methods, and the electronic device and the target resource device are devices in transmission networks corresponding to different network transmission methods, the electronic device cannot send a network access request from the terminal to the target resource device through the transmission network corresponding to the network transmission method to which the electronic device belongs.

[0122] In this scenario, because a VPN tunnel is established between the electronic device and the target resource device, and this VPN tunnel is a direct communication tunnel between the electronic device and the target resource device, the electronic device can send a target network access request to the target resource device through the VPN tunnel.

[0123] Optionally, a VPN tunnel can be established via fiber optic cable between an electronic device and the target resource device.

[0124] Optionally, a VPN tunnel can be established using methods such as Generic Routing Encapsulation (GRE), Layer Two Tunnel Protocol (L2TP), Internet Protocol Security (IPSec), or Security Socket Layer (SSL), or it can be a Multi Protocol Label Switching (MPLS) VPN tunnel.

[0125] It should be understood that when the VPN tunnel is an MPLS VPN tunnel, the method of establishing the VPN tunnel is relatively simple.

[0126] Optionally, the electronic device can determine the network transmission method to which the target network access address belongs and send network access requests to the target resource device through a VPN tunnel through policy traffic engineering (TE).

[0127] It should be noted that since the electronic device and the target resource device are connected through a direct communication tunnel, the electronic device does not need to go through multiple nodes of the backbone network and the education network when sending the target network access request to the target resource device through the VPN tunnel, thereby reducing the transmission latency of communication services.

[0128] Correspondingly, when the transmission network corresponding to the network transmission method of the target network access address is the same as the transmission network corresponding to the network transmission method of the electronic device, it indicates that the target resource device accessed by the terminal and the transmission network corresponding to the network transmission method of the electronic device are the same. In this case, the electronic device sends a network access request to the target resource device through the transmission network corresponding to the network transmission method of the electronic device.

[0129] For example, Figure 12 A schematic diagram of a direct communication tunnel is shown. (For example...) Figure 12 As shown, assuming the transmission network corresponding to the second network transmission method is the operator network, the transmission network corresponding to the first network transmission method is the campus network within the campus, and the BAS and interconnection gateway device are not integrated into a single electronic device, the starting point of the VPN tunnel can be the BAS1205 in the operator network, and the ending point can be the switch 1212 or firewall device 1214 corresponding to the campus network.

[0130] Optionally, a VPN tunnel can be established via fiber optic cable between the BAS and the campus intranet's switching equipment.

[0131] Another option is to establish a VPN tunnel via fiber optic cable between the BAS and the campus intranet firewall.

[0132] It's important to note that when the BAS and interconnection gateway are not integrated into a single electronic device, the BAS can determine the target resource device corresponding to the target network access address, and the interconnection gateway can determine the target domain name resolution device corresponding to the target domain name information. In this case, operations that would normally be performed by a single electronic device are now performed separately by the BAS and the interconnection gateway. Because a single electronic device simultaneously performs both the tasks of determining the target resource device corresponding to the target network access address and the target domain name resolution device corresponding to the target domain name information, it is prone to congestion due to the large amount of data being processed. By having all operations performed by a single electronic device performed separately by the BAS and the interconnection gateway, the number of operations performed by the BAS and the interconnection gateway is reduced, making congestion less likely.

[0133] In some embodiments, combined with Figure 10 ,like Figure 13 As shown, before the electronic device receives the network access request sent by the terminal, the network access method provided in this application embodiment further includes:

[0134] S1301, Electronic devices receive target domain name information sent by the terminal.

[0135] Specifically, before sending a network access request, the terminal needs to obtain the target network access address through the target domain name information. Therefore, the terminal can send the target domain name information to the electronic device before sending the network access request. Correspondingly, the electronic device can receive the target domain name information sent by the terminal and send it to the target domain name resolution device, so that the target domain name resolution device can resolve the target domain name information and thus determine the target network access address corresponding to the target domain name information.

[0136] S1302. The electronic device reads the correspondence between domain name information and network transmission method, determines the target network transmission method corresponding to the target domain name information, and sends the target domain name information to the target domain name resolution device corresponding to the target network transmission method.

[0137] Specifically, because electronic devices store the mapping between domain name information and network transmission methods, they can read this mapping and determine the target network transmission method corresponding to the target domain name information. Then, when the network transmission method of the electronic device differs from the target network transmission method corresponding to the target domain name information, the electronic device can send the target domain name information to the target domain name resolution device corresponding to the target network transmission method via a VPN tunnel.

[0138] Optionally, when the BAS and the interconnection gateway device are not integrated, the operation of the electronic device reading the correspondence between domain name information and network transmission method, determining the target network transmission method corresponding to the target domain name information, and sending the target domain name information to the target domain name resolution device corresponding to the target network transmission method can be performed by the interconnection gateway device.

[0139] Optionally, of the first network transmission method and the second network transmission method, one can be a public network transmission method and the other can be a private network transmission method.

[0140] For example, suppose that in the first network transmission method and the second network transmission method, one is a broadband network provided by an operator and the other is a campus network provided by a university, and the BAS and the interconnection gateway device are not integrated into a single electronic device. Figure 14 A schematic diagram illustrating a process of a terminal accessing a domain name resolution device via a broadband network is shown. Figure 14 As shown, the process of a terminal accessing a domain name resolution device through a broadband network includes:

[0141] S1401, The terminal sends the target domain name information to the BAS.

[0142] Combination Figure 13 For details on how the terminal sends target domain name information to the BAS, please refer to the relevant description in S1301, which will not be repeated here.

[0143] After receiving the target domain name information, S1402 and BAS send the target domain name information to the interconnection gateway device.

[0144] Combination Figure 13 After receiving the target domain name information, the BAS sends the target domain name information to the interconnection gateway device. For details on this, please refer to the relevant description in S1302. It will not be repeated here.

[0145] S1403. After receiving the target domain name information, the interconnection gateway device determines whether the target domain name information is the domain name information corresponding to the campus network.

[0146] Combination Figure 13 After receiving the target domain name information, the interconnection gateway device determines whether the target domain name information is the domain name information corresponding to the campus network. For the relevant description, please refer to the relevant description in S1302, which will not be repeated here.

[0147] S1404. When the target domain name information is the domain name information corresponding to the campus network, the interconnection gateway device sends the target domain name information to the domain name resolution device corresponding to the campus network through the VPN tunnel.

[0148] Combination Figure 13When the target domain name information is the domain name information corresponding to the campus network, the interconnection gateway device sends the target domain name information to the domain name resolution device corresponding to the campus network through the VPN tunnel. For the relevant description, please refer to the relevant description in S1302, which will not be repeated here.

[0149] S1405. When the target domain name information is not the domain name information corresponding to the campus network, the interconnection gateway device returns the target domain name information to the BAS through the broadband network. Then, the BAS sends the target domain name information to the domain name resolution device corresponding to the public network.

[0150] Combination Figure 13 When the target domain name information is not the domain name information corresponding to the campus network, the interconnection gateway device returns the target domain name information to the BAS through the broadband network. After that, the BAS sends the target domain name information to the domain name resolution device corresponding to the public network. For relevant descriptions, please refer to the relevant description in S1302, which will not be repeated here.

[0151] S1406, BAS receives the network access address sent by the domain name resolution device, and then sends the network access address to the terminal.

[0152] Combination Figure 13 The BAS receives the network access address sent by the domain name resolution device and then sends the network access address to the terminal. For details on this, please refer to the relevant descriptions in S1303 and S1304, which will not be repeated here.

[0153] In another possible method, one of the first network transmission method and the other of the second network transmission method can be a first dedicated network transmission method and the other can be a second dedicated network transmission method.

[0154] For example, suppose the first dedicated network transmission method is the network transmission method of the first enterprise, and the second dedicated network transmission method is the network transmission method of the second enterprise. The electronic device can receive domain name information sent by the first enterprise's terminal through the transmission network corresponding to the first dedicated network transmission method, and then determine whether the domain name information corresponds to the second enterprise's second dedicated network transmission method. If the domain name information corresponds to the second dedicated network transmission method, the electronic device will send the domain name information to the domain name resolution device corresponding to the second dedicated network transmission method. If the domain name information does not correspond to the second dedicated network transmission method, the electronic device will send the domain name information to the domain name resolution device corresponding to the first dedicated network transmission method.

[0155] Optionally, the domain name resolution device can be a Domain Name System (DNS) server.

[0156] Optionally, the electronic device can determine the target domain name information and the target network transmission method, and send the target domain name information to the target domain name resolution device through a VPN tunnel, through a policy TE.

[0157] Correspondingly, when the network transmission method to which the electronic device belongs is the same as the target network transmission method corresponding to the target domain name information, the electronic device can send the target domain name information to the target domain name resolution device corresponding to the target network transmission method according to the transmission network corresponding to the target network transmission method.

[0158] It should be noted that when the correspondence between domain name information and network transmission method is updated, electronic devices can update the correspondence between domain name information and network transmission method.

[0159] Correspondingly, when the mapping between network access addresses and resource devices is updated, electronic devices can also update the mapping between network access addresses and resource devices.

[0160] S1303. The electronic device receives the target network access address sent by the target domain name resolution device.

[0161] The target network access address is obtained by resolving the target domain name information.

[0162] Specifically, after the electronic device sends the target domain name information to the target domain name resolution device corresponding to the target network transmission method, the target domain name resolution device resolves the target domain name information to obtain the target network access address. Then, the target domain name resolution device can send the target network access address to the electronic device, enabling the electronic device to send the target network access address to the terminal.

[0163] S1304. The electronic device sends the target network access address to the terminal so that the terminal generates a network access request based on the target network access address.

[0164] Specifically, after receiving the target network access address from the target domain name resolution device, the electronic device can send the target network access address to the terminal. Subsequently, after receiving the target network access address, the terminal can generate a network access request based on the target network access address, so that the terminal can access the target resource device corresponding to the target domain name information according to the network access request.

[0165] In some embodiments, combined with Figure 13 ,like Figure 15 As shown, before receiving the target domain name information sent by the terminal, the electronic device needs to authenticate the information to obtain a private network IP address. Network access methods also include:

[0166] S1501, The electronic device receives the Internet Protocol (IP) address request message sent by the terminal and sends the IP address request message to the PORTAL WEB device.

[0167] Among them, the IP address request message is used to request the terminal's private network IP address.

[0168] Specifically, since each terminal needs to obtain an IP address before it can access the resource device corresponding to that network access address, the terminal can send an IP address request message to the electronic device to obtain an IP address. In this case, the electronic device can receive the IP address request message sent by the terminal. Then, the electronic device sends an IP address request message to the PORTALWEB device.

[0169] For example, Table 1 shows a schematic table of messages received or forwarded by an electronic device. As shown in Table 1, NO is the sequence number of the message received or sent by the electronic device (i.e., network access request, target domain name information, etc. in this application), TIME is the time the electronic device receives or sends the message, SOURCE is the source IP address of the message received or sent by the electronic device (i.e., the IP address of the device initiating the message, such as the private network IP address of the terminal initiating the network access request), DESTINATION is the target IP address of the message received or sent by the electronic device (such as the target network access address in this application), PROTOCOL is the protocol used by the message, LENGTH is the length of the message, and INFO is the information in the message. DNS domain name resolution messages are messages containing domain name information received by the BAS and messages containing domain name information sent by the BAS. Transmission Control Protocol (TCP) connection messages are TCP protocol messages captured by the BAS used to establish a connection between the terminal and the target device (such as the PORTAL WEB device in this application). The HyperText Transfer Protocol (HTTP) 302 redirect message is the message from the BAS receiving terminal and the message from the forwarding terminal to the PORTAL WEB device.

[0170] Table 1

[0171]

[0172]

[0173] S1502. The electronic device receives the prompt information generated by the PORTAL WEB device based on the IP address request message and sends the prompt information to the terminal.

[0174] The prompt message is used to prompt the terminal to send authentication information.

[0175] Specifically, after receiving the IP address request message from the terminal, the PORTAL WEB device can send a prompt message to the terminal, so that the terminal can send authentication information to the electronic device.

[0176] Optionally, the prompt information may include a web page that prompts the user to enter authentication information.

[0177] Optionally, the authentication information can be an account and password.

[0178] S1503. The electronic device receives the authentication information sent by the terminal and sends the authentication information to the PORTAL authentication device.

[0179] The authentication information is used to instruct the PORTAL authentication device to send authentication information to the remote user dial-up authentication RADIUS device, and to instruct the RADIUS device to authenticate the authentication information.

[0180] Specifically, after receiving the authentication information from the terminal, the electronic device forwards the authentication information to the PORTALWEB device. Then, the PORTAL WEB device sends the authentication information to the PORTAL authentication device. Upon receiving the authentication information, the PORTAL authentication device can encapsulate the authentication information using the PORTAL protocol with User Datagram Protocol (UDP), and then send the UDP-encapsulated authentication information to the electronic device via the Challenge Handshake Authentication Protocol (CHAP) authentication method. Next, the electronic device can extract the authentication information from the received UDP-encapsulated authentication information, encapsulate it into a RADIUS message, and send the RADIUS message to the RADIUS device.

[0181] Subsequently, the RADIUS device can authenticate the authentication information in the received RADIUS message. Once the authentication information is successfully authenticated, the RADIUS device sends a PORTAL authentication confirmation message to the PORTAL authentication device.

[0182] Optionally, the RADIUS device or PORTAL authentication device may use two-layer PORTAL technology or three-layer PORTAL technology to authenticate the authentication information. This application embodiment does not limit this.

[0183] It should be noted that Layer 2 portal technology refers to a direct communication connection between the terminal and the electronic device, or a connection between the terminal and the electronic device consisting only of a Layer 2 device. Layer 3 portal technology refers to a connection between the terminal and the BAS (Browser Automation System) via a Layer 3 device.

[0184] Referring to the above examples and Table 1, as shown in Table 2. Table 2 illustrates a schematic table of authentication information messages sent by a terminal. In this table, the HTTP message represents the authentication information message sent by the terminal, and userName (e.g., username test01) and userPwd (e.g., password test01) are the authentication information used in this application.

[0185] Table 2

[0186]

[0187] Table 3 shows a schematic table of UDP packets sent by a PORTAL authentication device. As shown in Table 3, the UDP packets are the authentication information encapsulated in UDP in this application. 50100→2000 are the port numbers sent by the PORTAL authentication device.

[0188] Table 3

[0189]

[0190]

[0191] Table 4 shows a schematic table of RADIUS messages sent by an electronic device. As shown in Table 4, RADIUS messages are messages sent by the electronic device to the RADIUS device.

[0192] Table 4

[0193]

[0194] S1504. In response to the received authentication confirmation message indicating successful authentication of the authentication information, the electronic device determines the private network IP address of the terminal and sends the private network IP address to the terminal.

[0195] Specifically, after receiving the PORTAL authentication response message, the PORTAL authentication device can generate an authentication confirmation message indicating successful authentication. After receiving the authentication confirmation message from the RADIUS device, the electronic device can determine the terminal's private network IP address. Then, the electronic device can send the private network IP address to the terminal.

[0196] Optionally, the electronic device determines the terminal's private network IP address by obtaining an IP address from a preset IP resource pool and setting this IP address as the terminal's private network IP address.

[0197] It should be noted that before sending an IP address request message to the electronic device, the terminal can also dynamically request a temporary IP address from a Dynamic Host Configuration Protocol (DHCP) server. The electronic device then uses this temporary IP address to access specific resources, such as pages where users input authentication information. Subsequently, after receiving the dedicated network IP address from the electronic device, the terminal releases this temporary IP address.

[0198] Alternatively, the DHCP server can also be an electronic device.

[0199] Optionally, the terminal can authenticate the authentication information using either the Point-to-Point Protocol over Ethernet (PPPoE) or the IP over Ethernet (IPOE) protocol. This application embodiment does not limit the method.

[0200] Based on the examples above, Table 5 shows a schematic table of authentication confirmation messages. As shown in Table 5, the HTTP 200 OK message is the authentication confirmation message used in this application to indicate that the authentication information has been successfully authenticated.

[0201] Table 5

[0202]

[0203] Combination Figure 15 , Figure 16 This diagram illustrates a process for a terminal to obtain an IP address. Assuming the electronic device is a BAS (Building Automation System), the process for the terminal to obtain a private network IP address is as follows: Figure 16 As shown:

[0204] S1601, The terminal sends an IP address request message to the BAS.

[0205] Combination Figure 11 The description of the terminal sending an IP address request message to the BAS can be found in the relevant description of S1101, and will not be repeated here.

[0206] S1602, BAS sends an IP address request message to the PORTAL WEB device.

[0207] Combination Figure 11 The description of how BAS sends IP address request messages to the PORTAL WEB device can be found in the description of S1101, and will not be repeated here.

[0208] S1603, PORTAL WEB device sends a prompt message to BAS.

[0209] Combination Figure 11 The description of how the PORTAL WEB device sends a prompt message to the BAS can be found in the relevant description of S1102, and will not be repeated here.

[0210] S1604, BAS sends a prompt message to the terminal.

[0211] Combination Figure 11 The description of how BAS sends prompts to the terminal can be found in the description of S1102, and will not be repeated here.

[0212] S1605, The terminal sends authentication information to the BAS.

[0213] Combination Figure 11 For details on how the terminal sends authentication information to the BAS, please refer to the relevant description in S1103, which will not be repeated here.

[0214] S1606 and BAS send authentication information to the PORTAL authentication device.

[0215] Combination Figure 11 For details on how BAS sends authentication information to the PORTAL authentication device, please refer to the relevant description in S1103. It will not be repeated here.

[0216] S1607, PORTAL authentication device sends UDP-encapsulated authentication information to BAS.

[0217] Combination Figure 11 For a description of how the PORTAL authentication device sends UDP-encapsulated authentication information to the BAS, please refer to the relevant description in S1103, which will not be repeated here.

[0218] S1608 and BAS send RADIUS messages to the RADIUS device.

[0219] Combination Figure 11 For a description of how BAS sends RADIUS messages to the RADIUS device, please refer to the relevant description in S1103, which will not be repeated here.

[0220] S1609, the RADIUS device sends a PORTAL authentication response message to the PORTAL authentication device.

[0221] Combination Figure 11 The description of how the RADIUS device sends the PORTAL authentication response message to the PORTAL authentication device can be found in the relevant description in S1104, and will not be repeated here.

[0222] S1610, the PORTAL authentication device sends an authentication confirmation message to the PORTAL WEB device to indicate that the authentication information has been successfully authenticated.

[0223] Combination Figure 11 The description of the authentication confirmation message sent by the PORTAL authentication device to the PORTAL WEB device to indicate successful authentication can be found in the relevant description in S1104, and will not be repeated here.

[0224] S1611, BAS determines the terminal's private network IP address and sends the terminal's private network IP address to the terminal.

[0225] Combination Figure 11 The BAS determines the terminal's private network IP address and sends the relevant description of the terminal's private network IP address to the terminal. For details, please refer to the relevant description in S1104, which will not be repeated here.

[0226] In some embodiments, combined with Figure 15 ,like Figure 17 As shown, the network access method provided in this application embodiment further includes:

[0227] S1701, The electronic device receives the message to be transmitted from the terminal.

[0228] The message to be transmitted includes the terminal's private network IP address.

[0229] Specifically, when a terminal accesses a resource device corresponding to a network access address, the terminal can send a message to be transmitted to the electronic device. The electronic device can then receive the message. When the network transmission mode of the resource device accessed by the terminal is a private network transmission mode, the terminal uses its private network IP address to access the resource device. Therefore, the message to be transmitted includes the terminal's private network IP address.

[0230] S1702. The electronic device determines the public IP address of the terminal corresponding to the private network IP address based on the correspondence between the private network IP address and the public network IP address, and updates the private network IP address of the terminal to the public network IP address of the terminal.

[0231] In the mapping relationship between private network IP addresses and public network IP addresses, one public network IP address corresponds to multiple private network IP addresses.

[0232] Specifically, when a terminal accesses resource devices using a private network transmission method, it uses its private network IP address. However, when a terminal accesses resource devices using a public network transmission method, its private network IP address is insufficient. Therefore, the electronic device can determine the corresponding public network IP address based on the mapping between private and public network IP addresses. Subsequently, the electronic device can update the terminal's private network IP address to its public network IP address, enabling the terminal to access resource devices using the public network transmission method.

[0233] It should be noted that, since the number of public IP addresses is relatively small while the number of private IP addresses is relatively large, electronic devices can use Carrier-Grade Network Address Translation (CGN) technology to reuse public IP addresses, thereby improving the utilization rate of public IP addresses.

[0234] CGN stands for Carrier-grade Network Address Translation (NAT), which maps multiple private network IP addresses to a single public IP address. In this scenario, a terminal can access resource devices corresponding to a private network transmission method using its private network IP address, or it can determine its public IP address through the mapping between private network IP addresses and public IP addresses, allowing it to access resource devices corresponding to a public network transmission method using its public IP address.

[0235] Figure 18 A comparative diagram of CGN and NAT is shown. (For example...) Figure 18 As shown, CGN has advantages over traditional NAT, such as large capacity, low performance, high reliability, NAT logging, and user manageability.

[0236] Correspondingly, when the network transmission method corresponding to the message to be transmitted is private network transmission, the electronic device does not need to update the private network IP address to a public network IP address.

[0237] S1703. The electronic device sends the updated message to be transmitted.

[0238] The updated message to be transmitted includes the terminal's public IP address.

[0239] Specifically, when the network transmission method corresponding to the message to be transmitted is private network transmission, the electronic device updates the message to be transmitted, that is, the electronic device adds the public IP address corresponding to the terminal's private network IP address to the message to be transmitted. Then, the electronic device sends the updated message to be transmitted, so that the terminal can access the resource devices corresponding to the public network transmission method based on the public IP address corresponding to the private network IP address.

[0240] Correspondingly, when the network transmission mode corresponding to the message to be transmitted is the private network transmission mode, the electronic device does not update the message to be transmitted and sends the message to be transmitted, so that the terminal can access the resource device corresponding to the private network transmission mode according to the terminal's private network IP address.

[0241] In some embodiments, the above description mainly focuses on the various steps of the network access method provided in this application. The complete flow of the network access method provided in this application is then described below in conjunction with the above embodiments. For example... Figure 19 As shown, the network access method provided in this application embodiment specifically includes:

[0242] S1901, The terminal initiates an IP address request message.

[0243] Combination Figure 15 For a description of the terminal initiating an IP address request message, please refer to the relevant description in S1501, which will not be repeated here.

[0244] S1902 and BAS receive IP address request messages and then send IP address request messages to the PORTAL WEB device.

[0245] Combination Figure 15 The description of how BAS receives IP address request messages and then sends them to the PORTAL WEB device can be found in the relevant description of S1501, and will not be repeated here.

[0246] S1903 and PORTAL WEB devices send notification messages to the terminal via BAS.

[0247] Combination Figure 15 For a description of how the PORTAL WEB device sends prompts to the terminal via BAS, please refer to the relevant description in S1502, which will not be repeated here.

[0248] S1904. The terminal sends authentication information to the PORTAL WEB device via BAS.

[0249] Combination Figure 15 For details on how the terminal sends authentication information to the PORTAL WEB device via BAS, please refer to the relevant description in S1503, which will not be repeated here.

[0250] S1905, the PORTAL WEB device sends authentication information to the PORTAL authentication device.

[0251] Combination Figure 15 For details on how the PORTAL WEB device sends authentication information to the PORTAL authentication device, please refer to the relevant description in S1503, which will not be repeated here.

[0252] S1906. The PORTAL authentication device uses the PORTAL protocol to encapsulate the authentication information into UDP, and then sends the UDP-encapsulated authentication information to the electronic device via CHAP.

[0253] Combination Figure 15 The PORTAL authentication device uses the PORTAL protocol to encapsulate the authentication information into UDP and then sends the UDP-encapsulated authentication information to the electronic device via CHAP. For a related description, please refer to the relevant description in S1503, which will not be repeated here.

[0254] S1907 and BAS extract authentication information from the authentication information encapsulated in UDP, then encapsulate the authentication information into a RADIUS message and send the RADIUS message to the RADIUS device.

[0255] Combination Figure 15 BAS extracts authentication information from the authentication information encapsulated by UDP, then encapsulates the authentication information into a RADIUS message and sends the RADIUS message to the RADIUS device. For a related description, please refer to the relevant description in S1503, which will not be repeated here.

[0256] S1908 The RADIUS device authenticates the authentication information in the received RADIUS message, and after successful authentication, sends a PORTAL authentication response message to the PORTAL authentication device.

[0257] Combination Figure 15 The RADIUS device authenticates the authentication information in the received RADIUS message. After successful authentication, it sends a PORTAL authentication response message to the PORTAL authentication device. For details on this, please refer to the relevant description in S1503. It will not be repeated here.

[0258] After receiving the PORTAL authentication response message, the S1909 PORTAL authentication device sends an authentication confirmation message to the BAS to indicate that the authentication was successful.

[0259] Combination Figure 15After receiving the PORTAL authentication response message, the PORTAL authentication device sends an authentication confirmation message to the BAS to indicate successful authentication. For details on this, please refer to the relevant description in S1503, which will not be repeated here.

[0260] After receiving the authentication confirmation message, S1910 and BAS select an IP address from the IP address resource pool to determine the terminal's IP address and send the IP address to the terminal.

[0261] Combination Figure 17 After receiving the authentication confirmation message, BAS selects an IP address from the IP address resource pool to determine the terminal's IP address and sends the IP address to the terminal. For relevant descriptions of the IP address, please refer to the relevant description in S1504, which will not be repeated here.

[0262] S1911. When a terminal accesses a resource device, it sends a network access request to the BAS. The BAS then determines whether the terminal's IP address is a public IP address.

[0263] Combination Figure 17 When a terminal accesses a resource device, it sends a network access request to the BAS. The description of how the BAS determines whether the terminal's IP address is a public IP address can be found in section S1701, and will not be repeated here.

[0264] S1912. When the terminal's IP address is not a public IP address, BAS maps the private network IP address to a public IP address through CGN.

[0265] Combination Figure 17 When the terminal's IP address is not a public IP address, the relevant description of how BAS maps the private network IP address to a public IP address through CGN can be found in the relevant description in S1702, and will not be repeated here.

[0266] S1913 and BAS access resource devices via public IP addresses.

[0267] Combination Figure 20 For details on how BAS accesses resource devices via public IP addresses, please refer to the relevant description in S1702, which will not be repeated here.

[0268] For example, Figure 20 This diagram illustrates the effect of applying the network access method provided in the embodiments of this application. For example... Figure 20 As shown, assuming this application is applied to users in universities, by Figure 21It can be seen that from 2017 to 2020, the growth trajectory of university users was relatively slow when the network access method provided in the embodiments of this application was not applied. However, after the network access method provided in the embodiments of this application was applied in 2021, the growth of university users was relatively rapid.

[0269] Based on an average revenue per user (ARPU) of 50 yuan per month (mobile phone + broadband) for each student package, the profitability is evaluated. The company is expected to continuously increase revenue by more than 2,000 students per year, resulting in a monthly increase of 100,000 yuan and an annual increase of more than 1.2 million yuan.

[0270] For example, Figure 21 This diagram illustrates yet another effect of applying the network access method provided in the embodiments of this application. For example... Figure 22 As shown, after applying the network access method provided in this application embodiment, the latency of internet access for university users is significantly reduced. This application can optimize network latency by 80%-90%, achieving converged broadband, low latency in smart campuses, and practical network reshaping. It has played a demonstrative role in the university field, providing diversified innovation and large-scale connectivity empowerment.

[0271] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0272] This application embodiment can divide the network access device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0273] like Figure 10 The diagram shown is a structural schematic of a network access device provided in an embodiment of this application. This network access device can be used to perform... Figure 13 , Figure 15 , Figure 17 , Figure 22Any of the methods for network access shown in the examples. Figure 10 The network access device shown includes: a receiving unit 2201, a reading unit 2202, a processing unit 2203, and a sending unit 2204;

[0274] The receiving unit 2201 is used to receive a network access request sent by the terminal; the network access request includes a target network access address. For example, in combination with... Figure 10 The receiving unit 2201 is used to execute S1001.

[0275] The reading unit 2202 is used to read the correspondence between network access addresses and resource devices. For example, combined with... Figure 10 The reading unit 2202 is used to execute S1002.

[0276] Processing unit 2203 is used to determine the target resource device corresponding to the target network access address; the correspondence includes the correspondence between network access address and resource device in the first network transmission mode and the correspondence between network access address and resource device in the second network transmission mode. For example, combined with Figure 10 The processing unit 2203 is used to execute S1002.

[0277] The sending unit 2204 is configured to send a network access request to the target resource device via a Virtual Private Network (VPN) tunnel when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device. For example, combined with... Figure 13 The sending unit 2204 is used to execute S1003.

[0278] Optionally, the receiving unit 2201 is also configured to receive target domain name information sent by the terminal. For example, in combination with Figure 13 The receiving unit 2201 is used to execute S1301.

[0279] The reading unit 2202 is also used to read the correspondence between domain name information and network transmission methods. For example, combined with... Figure 13 The reading unit 2202 is used to execute S1302.

[0280] The processing unit 2203 is also used to determine the target network transmission method corresponding to the target domain name information. For example, in combination with Figure 13 The processing unit 2203 is used to execute S1302.

[0281] The sending unit 2204 is also used to send target domain name information to the target domain name resolution device corresponding to the target network transmission method. For example, in combination with Figure 13The sending unit 2204 is used to execute S1302.

[0282] The receiving unit 2201 is also used to receive the target network access address sent by the target domain name resolution device; the target network access address is obtained by resolving the target domain name information. For example, combined with Figure 13 The receiving unit 2201 is used to execute S1303.

[0283] The sending unit 2204 is also configured to send a target network access address to the terminal, so that the terminal generates a network access request based on the target network access address. For example, in combination with Figure 15 The sending unit 2204 is used to execute S1304.

[0284] Optionally, the receiving unit 2201 is also configured to receive an Internet Protocol (IP) address request message sent by the terminal. For example, in combination with... Figure 15 The receiving unit 2201 is used to execute S1501.

[0285] The sending unit 2204 is also used to send an IP address request message to the portal web device; the IP address request message is used to request a private network IP address for the terminal. For example, combined with... Figure 15 The sending unit 2204 is used to execute S1501.

[0286] The receiving unit 2201 is also used to receive prompt information generated by the PORTAL WEB device based on the IP address request message. For example, combined with Figure 15 The receiving unit 2201 is used to execute S1502.

[0287] The sending unit 2204 is also used to send a prompt message to the terminal; the prompt message is used to prompt the terminal to send authentication information. For example, combined with... Figure 15 The sending unit 2204 is used to execute S1502.

[0288] The receiving unit 2201 is also used to receive authentication information sent by the terminal. For example, in combination with... Figure 15 The receiving unit 2201 is used to execute S1503.

[0289] The sending unit 2204 is also used to send authentication information to the PORTAL authentication device; the authentication information is used to instruct the PORTAL authentication device to send authentication information to the remote user dial-up authentication RADIUS device, and to instruct the RADIUS device to authenticate the authentication information. For example, in combination with Figure 15 The sending unit 2204 is used to execute S1503.

[0290] Processing unit 2203 is also configured to determine the private network IP address of the terminal in response to a received authentication confirmation message indicating successful authentication of the authentication information. For example, in combination with Figure 15 The processing unit 2203 is used to execute S1504.

[0291] The sending unit 2204 is also used to send the private network IP address to the terminal. For example, in combination with... Figure 17 The sending unit 2204 is used to execute S1504.

[0292] Optionally, the receiving unit 2201 is also used to receive a message to be transmitted sent by the terminal; the message to be transmitted includes the terminal's private network IP address. For example, combined with... Figure 17 The receiving unit 2201 is used to execute S1701.

[0293] Processing unit 2203 is also used to determine the public IP address of the terminal corresponding to the private network IP address based on the mapping relationship between private network IP addresses and public network IP addresses. For example, combined with Figure 17 The processing unit 2203 is used to execute S1702.

[0294] Processing unit 2203 is also used to update the terminal's private network IP address to the terminal's public network IP address; in the mapping relationship between private network IP addresses and public network IP addresses, one public network IP address corresponds to multiple private network IP addresses. For example, combined with Figure 17 The processing unit 2203 is used to execute S1702.

[0295] The sending unit 2204 is also used to send an updated message to be transmitted; the updated message to be transmitted includes the terminal's public IP address. For example, combined with... ​ The sending unit 2204 is used to execute S1703.

[0296] This application also provides a computer-readable storage medium, which includes computer-executable instructions that, when executed on a computer, cause the computer to perform the network access method provided in the above embodiments.

[0297] This application also provides a computer program that can be directly loaded into a memory and contains software code. After being loaded and executed by a computer, the computer program can implement the network access method provided in the above embodiments.

[0298] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.

[0299] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0300] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and other division methods may exist in actual implementation. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate; components shown as units may be one physical unit or multiple physical units, i.e., they may be located in one place or distributed in multiple different places. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0301] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0302] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A network access method, characterized in that, Applied to electronic devices, the electronic devices are broadband access network (BAS) servers, and the electronic devices are used to split network access requests in public network transmission mode and network access requests in private network transmission mode; The network access method includes: The receiving terminal sends a network access request; the network access request includes a target network access address. Read the correspondence between network access addresses and resource devices, and determine the target resource device corresponding to the target network access address; the correspondence includes the correspondence between network access addresses and resource devices in the first network transmission mode and the correspondence between network access addresses and resource devices in the second network transmission mode; When the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode, the network access request is sent to the target resource device through a Virtual Private Network (VPN) tunnel; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device. When the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the second network transmission mode, and the second network transmission mode is a public network transmission mode, the network access request is sent to the target resource device via the Internet.

2. The network access method according to claim 1, characterized in that, Before receiving a network access request from a terminal, the network access method further includes: Receive the target domain name information sent by the terminal; Read the correspondence between domain name information and network transmission method, determine the target network transmission method corresponding to the target domain name information, and send the target domain name information to the target domain name resolution device corresponding to the target network transmission method; Receive the target network access address sent by the target domain name resolution device; the target network access address is obtained by resolving the target domain name information; The target network access address is sent to the terminal so that the terminal generates the network access request based on the target network access address.

3. The network access method according to claim 1 or 2, characterized in that, The network access method further includes: The system receives an Internet Protocol (IP) address request message from the terminal and sends the IP address request message to the portal web device; the IP address request message is used to request a private network IP address from the terminal. The system receives a prompt message generated by the PORTAL WEB device based on the IP address request message and sends the prompt message to the terminal; the prompt message is used to prompt the terminal to send authentication information. The system receives authentication information sent by the terminal and sends the authentication information to the PORTAL authentication device. The authentication information is used to instruct the PORTAL authentication device to send the authentication information to the remote user dial-up authentication RADIUS device, and to instruct the RADIUS device to authenticate the authentication information. In response to the received authentication confirmation message indicating successful authentication of the authentication information, the private network IP address of the terminal is determined and the private network IP address is sent to the terminal.

4. The network access method according to claim 3, characterized in that, Also includes: Receive a message to be transmitted sent by the terminal; the message to be transmitted includes the private network IP address of the terminal; Based on the mapping relationship between private network IP addresses and public network IP addresses, determine the public network IP address of the terminal corresponding to the private network IP address of the terminal, and update the private network IP address of the terminal to the public network IP address of the terminal; in the mapping relationship between private network IP addresses and public network IP addresses, one public network IP address corresponds to multiple private network IP addresses; Send an updated message to be transmitted; the updated message to be transmitted includes the public IP address of the terminal.

5. A network access device, characterized in that, Applied to electronic devices, the electronic devices are BAS servers, and the electronic devices are used to split network access requests in public network transmission mode and network access requests in private network transmission mode; including: receiving unit, reading unit, processing unit and sending unit; The receiving unit is used to receive a network access request sent by the terminal; the network access request includes a target network access address; The reading unit is used to read the correspondence between network access addresses and resource devices; The processing unit is used to determine the target resource device corresponding to the target network access address; the correspondence includes the correspondence between the network access address and the resource device in the first network transmission mode and the correspondence between the network access address and the resource device in the second network transmission mode; The sending unit is configured to send the network access request to the target resource device through a Virtual Private Network (VPN) tunnel when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the first network transmission mode, and the first network transmission mode is a private network transmission mode; the VPN tunnel is a direct communication tunnel between the electronic device and the target resource device. The sending unit is further configured to send the network access request to the target resource device via the Internet when the electronic device belongs to the transmission network corresponding to the second network transmission mode, and the target network access address is the network access address corresponding to the second network transmission mode, and the second network transmission mode is a public network transmission mode.

6. The network access device according to claim 5, characterized in that, The receiving unit is also configured to receive target domain name information sent by the terminal; The reading unit is also used to read the correspondence between domain name information and network transmission methods; The processing unit is further configured to determine the target network transmission method corresponding to the target domain name information; The sending unit is further configured to send the target domain name information to the target domain name resolution device corresponding to the target network transmission method; The receiving unit is further configured to receive the target network access address sent by the target domain name resolution device; the target network access address is obtained by resolving the target domain name information; The sending unit is further configured to send the target network access address to the terminal, so that the terminal generates the network access request based on the target network access address.

7. The network access device according to claim 5 or 6, characterized in that, The receiving unit is also configured to receive an Internet Protocol (IP) address request message sent by the terminal; The sending unit is further configured to send the IP address request message to the PORTAL WEB device; the IP address request message is used to request the private network IP address of the terminal; The receiving unit is also configured to receive the prompt information generated by the PORTAL WEB device based on the IP address request message; The sending unit is further configured to send the prompting information to the terminal; the prompting information is used to prompt the terminal to send authentication information; The receiving unit is also used to receive authentication information sent by the terminal; The sending unit is further configured to send the authentication information to the PORTAL authentication device; the authentication information is used to instruct the PORTAL authentication device to send the authentication information to the remote user dial-up authentication RADIUS device, and to instruct the RADIUS device to authenticate the authentication information. The processing unit is further configured to determine the private network IP address of the terminal in response to a received authentication confirmation message indicating that the authentication information has been successfully authenticated; The sending unit is also used to send the private network IP address to the terminal.

8. The network access device according to claim 7, characterized in that, The receiving unit is further configured to receive a message to be transmitted sent by the terminal; the message to be transmitted includes the private network IP address of the terminal. The processing unit is further configured to determine the public IP address of the terminal corresponding to the private network IP address of the terminal based on the correspondence between the private network IP address and the public network IP address. The processing unit is further configured to update the private network IP address of the terminal to the public network IP address of the terminal; in the correspondence between the private network IP address and the public network IP address, one public network IP address corresponds to multiple private network IP addresses; The sending unit is further configured to send an updated message to be transmitted; the updated message to be transmitted includes the public IP address of the terminal.

9. A network access device, characterized in that, It includes a memory and a processor; the memory is used to store computer execution instructions, and the processor is connected to the memory via a bus; when the network access device is running, the processor executes the computer execution instructions stored in the memory to cause the network access device to perform the network access method as described in any one of claims 1-4.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform the network access method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Data transmission method and device

    CN110099129A

  • System and method to proxy inbound connections to privately addressed hosts

    US20030154306A1

  • Private network access

    US20230049547A1